The Central Electricity Authority (CEA) notified the Cyber Security in Power Sector Regulations, 2026 under the Electricity Act, 2003, effective from 1 April 2027.
The rules cover power generators, captive plants and energy storage systems with 50 megawatts (MW) or more capacity, along with power exchanges and over-the-counter trading platforms.
Computer Security Incident Response Team–Power (CSIRT-Power) is the nodal agency, and cyber incidents must also be reported to the Indian Computer Emergency Response Team (CERT-In).
General cyber incidents must be reported within six hours, while cyber sabotage of critical systems must be reported within 24 hours.
The rules require Operational Technology (OT) systems to be separated from Information Technology (IT) systems and sensitive power-sector data to be securely stored within India.